VDB
Sign up
HIGH7.5

GHSA-cc4v-rvgp-2pf3

Jawn: Uncontrolled nesting depth in JSON parser

Quick fix

GHSA-cc4v-rvgp-2pf3 — org.typelevel:jawn-parser_2.12: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.7.0</version> for org.typelevel:jawn-parser_2.12

Details

The Jawn parser before 1.6.1 is vulnerable to a denial of service attack via untrusted input.

### Impact

A remote attacker who can submit JSON to any jawn-backed parse method can exhaust JVM heap and trigger `java.lang.OutOfMemoryError`. This is treated by Scala as a fatal error and not typically handled by `scala.util.Try` or `cats.effect.IO`.

### Patches

Version `1.6.1` introduces a configurable nesting-depth limit (`Parser#maxDepth`, default `4096`). Inputs deeper than the limit fail with a recoverable `ParseException` instead of exhausting heap.

Users who require deeper nesting may override `maxDepth` on a `Parser` subclass.

### Workarounds

- Enforce an input size limit small enough that the resulting context stack cannot exhaust heap, (e.g. http4s `EntityLimiter`). - Pre-scan untrusted input and reject documents whose maximum delimiter nesting exceeds a threshold before handing them to jawn.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.typelevel:jawn-parser_2.12
Introduced in: 0Fixed in: 1.7.0
Fix# pom.xml: bump <version>1.7.0</version> for org.typelevel:jawn-parser_2.12
Maven/org.typelevel:jawn-parser_2.13
Introduced in: 0Fixed in: 1.7.0
Fix# pom.xml: bump <version>1.7.0</version> for org.typelevel:jawn-parser_2.13
Maven/org.typelevel:jawn-parser_3
Introduced in: 0Fixed in: 1.7.0
Fix# pom.xml: bump <version>1.7.0</version> for org.typelevel:jawn-parser_3

References